amaroK Web Frontend 1.3 stores the globals.inc file under the web root without a .php extension and insufficient access control, which allows remote attackers to obtain the database username and password via a direct request to the file.
Score: 3.0
Priority: P2 - Serious (High)
Score: 0.00654
Percentile:
0.69979
CVSS v2 Score: 7.5
Severity: